Book 6 of 14
Network Forensics & Traffic Analysis
Full-spectrum network visibility — from raw packet capture to production NSM, C2 detection, and cloud forensics
75
Chapters
13
Parts
50+
Working scripts
30+
Detection rules
Part 1 — Capture Infrastructure
Part 2 — Wireshark Mastery
Part 3 — tshark and tcpdump
Part 4 — Protocol-Level Analysis
- Ch 19Scapy Fundamentals
- Ch 20pyshark
- Ch 21dpkt and impacket
- Ch 22Automated IOC Extractors
- Ch 23Beaconing Detection in Python
- Ch 24HTTP and HTTPS Analysis
- Ch 25DNS Forensics
- Ch 26TLS Deep Dive
- Ch 27SMB Forensics
- Ch 28SMTP and Email Forensics
- Ch 29Kerberos in PCAP
- Ch 30HTTP/2 and QUIC
- Ch 31SSH and RDP
Part 5 — Fingerprinting and Decryption
Part 6 — Statistical Detection
Part 7 — C2 Traffic Identification
Part 8 — Zeek
Part 9 — Suricata
Part 10 — NetFlow & IPFIX
Part 11 — Arkime
Part 12 — Specific Attack Traffic